Pick your options and download a commented bash script, ready to review and run on your Debian or Ubuntu VPS.
Don't close your current SSH session
Before closing this terminal, open a second one and confirm you can connect with the new configuration. A mistake in the firewall or SSH setup can lock you out of your own server.
Generated script
#!/usr/bin/env bash
set -euo pipefail
# Generated by the SecuryBlack VPS hardening generator.
# Review every line before running it. Written for Debian/Ubuntu (apt + ufw) —
# other distros are not supported yet.
#
# IMPORTANT: keep this SSH session open. Open a SECOND terminal and confirm
# you can log in before closing this one — a mistake in the SSH or firewall
# config below can lock you out of your own server.
echo "1/4 Allowing SSH before enabling the firewall..."
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
echo "Enabling UFW..."
sudo ufw --force enable
echo "2/4 Installing fail2ban..."
sudo apt-get update
sudo apt-get install -y fail2ban
sudo systemctl enable --now fail2ban
echo "3/4 Hardening sshd_config..."
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin prohibit-password/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl restart sshd
echo "4/4 Enabling unattended security upgrades..."
sudo apt-get install -y unattended-upgrades
sudo dpkg-reconfigure -f noninteractive unattended-upgrades
echo "Done. Do NOT close this session — open a new terminal and confirm you can log in before disconnecting."FerroSentry applies this same hardening in under a minute when you connect your server, and keeps watching afterward — if something changes, it tells you.